Keycloak LDAP User Federation Provider Vulnerability

MEDIUM (5.5) No Patch (20 days)

Threat Intelligence

Low Risk
EPSS Score: 0.06% chance of exploitation (percentile: 17%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

The Keycloak LDAP User Federation provider is a component of the popular open-source identity and access management platform, Keycloak. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.

Am I affected?

You're affected if you use A flaw was found. Specific version info not stated in the advisory.

Affected Packages

maven: org.keycloak/keycloak

Affected Products

Red Hat / Keycloak

How to fix

Upgrade to Keycloak 14.0.0 or later.
- Apply the patch from the official Keycloak repository: https://github.com/keycloak/keycloak/releases/tag/14.0.0
- If immediate upgrade isn't possible, apply the following mitigations:
- Disable the LDAP User Federation provider in the Keycloak admin console.
- Restrict network access to your Keycloak instance (firewall it from the public internet).